# www.sonarsource.com llms-full.txt > Sonar provides tools for developers to improve code quality and security through continuous static analysis of both human-written and AI-generated code. This file is the comprehensive link index for LLM discovery and retrieval. For the lightweight discovery file, see: https://www.sonarsource.com/llms.txt --- ## Root - [Home](https://www.sonarsource.com/): To create an account and start improving code quality and security with cloud-based static analysis. --- ## Products ### SonarQube Core - [SonarQube](https://www.sonarsource.com/products/sonarqube/): To explore SonarSource’s solution for code quality and security through comprehensive static code analysis and continuous inspection. - [SonarQube Server](https://www.sonarsource.com/products/sonarqube/server/): To learn about the self-managed solution for code quality and security with advanced static analysis and governance capabilities. - [SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/): To discover the cloud-based solution for code quality and security with scalable static code analysis and seamless DevOps integration. - [Sign Up for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/signup/): To create an account and start improving code quality and security with cloud-based static analysis. - [Sign Up Free for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/signup-free/): To start using SonarQube Cloud with a free plan for automated code quality and security analysis. - [Contact SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/contact/): To get in touch with the team for questions about SonarQube Cloud and its code quality and security capabilities. - [Contact Enterprise Sales](https://www.sonarsource.com/products/sonarqube/cloud/contact-enterprise-sales/): Facilitate inquiries for SonarQube Cloud Enterprise sales and information. - [SonarQube Cloud Features](https://www.sonarsource.com/products/sonarqube/cloud/features/): Highlight SonarQube Cloud's enterprise features for code quality and security in software development. - [Contact Enterprise Sales for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/features/integrations/): To explore integrations that embed code quality and security checks directly into your CI/CD pipelines. - [SonarQube Cloud Roadmap](https://www.sonarsource.com/products/sonarqube/cloud/roadmap/): Outline upcoming features and updates for SonarQube Cloud, inviting user feedback on priorities. - [SonarQube Cloud Updates](https://www.sonarsource.com/products/sonarqube/cloud/whats-new/): Highlighting recent updates and features of SonarQube Cloud to enhance user experience. - [SonarQube Cloud New Pricing Plans](https://www.sonarsource.com/products/sonarqube/cloud/new-pricing-plans/): To review updated pricing options and plans for scaling code quality and security in the cloud. - [Advanced Security](https://www.sonarsource.com/products/sonarqube/advanced-security/): Solutions for the secure use of open-source code, including advanced Static Application Security Testing (SAST) and Software Composition Analysis (SCA). https://www.sonarsource.com/products/sonarqube/advanced-security/free-trial/ - [MCP Server](https://www.sonarsource.com/products/sonarqube/mcp-server/): To provide a free, local “Model Context Protocol” server that connects SonarQube (Cloud or Server) with AI-native IDEs and AI agents. - [SonarSweep](https://www.sonarsource.com/products/sonarsweep/): To provide a service that systematically remediates, optimizes, and secures coding datasets used to train coding-capable AI models (LLMs). ### Deployment - [SonarQube Deployment Overview](https://www.sonarsource.com/products/sonarqube/deployment/): To explore deployment options for SonarQube, including flexible environments that support scalable code quality and security analysis. - [Install SonarQube from ZIP](https://www.sonarsource.com/products/sonarqube/deployment/install-zip/): To learn how to install SonarQube using the ZIP distribution for manual, self-managed deployment. - [Deploy SonarQube with Docker](https://www.sonarsource.com/products/sonarqube/deployment/docker/): To run SonarQube in a containerized environment using Docker for simplified setup and consistent code quality and security analysis. - [Deploy SonarQube on Kubernetes](https://www.sonarsource.com/products/sonarqube/deployment/kubernetes/): To deploy SonarQube on Kubernetes for cloud-native scalability, resilience, and enterprise-grade code quality and security. ### Downloads - [SonarQube Downloads](https://www.sonarsource.com/products/sonarqube/downloads/): To access available editions of SonarQube for self-managed code quality and security analysis. - [SonarQube LTS Downloads](https://www.sonarsource.com/products/sonarqube/downloads/lts/): To download the Long-Term Support (LTS) version of SonarQube for stability-focused code quality and security management. - [SonarQube 9.9 LTS](https://www.sonarsource.com/products/sonarqube/downloads/lts/9-9-lts/): To download SonarQube 9.9 LTS for long-term stability and enterprise-grade code quality and security analysis. - [SonarQube 8.9 LTS](https://www.sonarsource.com/products/sonarqube/downloads/lts/8-9-lts/): To download SonarQube 8.9 LTS for legacy long-term support of code quality and security initiatives. - [Developer Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-developer-edition/): To confirm and proceed with the download of SonarQube Developer Edition for enhanced code quality and security features. - [Enterprise Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-enterprise-edition/): To confirm and proceed with the download of SonarQube Enterprise Edition for advanced governance and code quality and security controls. - [Data Center Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-data-center-edition/): To confirm and proceed with the download of SonarQube Data Center Edition for high availability and scalable code quality and security. - [Historical SonarQube Downloads](https://www.sonarsource.com/products/sonarqube/downloads/historical-downloads/): To access previous versions of SonarQube for legacy environments and migration support. - [SonarQube LTA Downloads](https://www.sonarsource.com/products/sonarqube/downloads/lta/): To download the Latest Active (LTA) version of SonarQube for up-to-date code quality and security capabilities. ### Editions - [SonarQube Developer Edition](https://www.sonarsource.com/products/sonarqube/developer-edition/): To learn about the Developer Edition of SonarQube that enhances code quality and security analysis with deeper insights and team collaboration features. - [SonarQube Enterprise Edition](https://www.sonarsource.com/products/sonarqube/enterprise-edition/): To explore the Enterprise Edition of SonarQube offering advanced governance, portfolio management, and comprehensive code quality and security controls. - [Upgrade to SonarQube Enterprise Edition](https://www.sonarsource.com/products/sonarqube/enterprise-edition/upgrade/): To find information on upgrading to the Enterprise Edition for expanded capabilities in code quality and security. - [SonarQube Data Center Edition](https://www.sonarsource.com/products/sonarqube/data-center-edition/): To discover the Data Center Edition of SonarQube designed for high availability, scalability, and robust code quality and security analysis across large organizations. ### What's New (All Versions) - [What’s New in SonarQube][https://www.sonarsource.com/products/sonarqube/whats-new/]: To explore the latest updates, enhancements, and improvements in SonarQube for advancing code quality and security. - [What’s New in SonarQube – Page 2](https://www.sonarsource.com/products/sonarqube/whats-new/2/): To browse additional SonarQube release updates and feature announcements. - [What’s New in SonarQube – Page 3](https://www.sonarsource.com/products/sonarqube/whats-new/3/): To review continued updates and historical release highlights for SonarQube. - [What’s New in SonarQube – Page 5](https://www.sonarsource.com/products/sonarqube/whats-new/5/): To access earlier SonarQube release notes and feature summaries. - [SonarQube 2025.2 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-2/): To learn about the new features and improvements introduced in SonarQube 2025.2. -[SonarQube 2025.3 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-3/): To discover enhancements and updates delivered in SonarQube 2025.3. -[SonarQube 2025.4 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-4/): To review the latest code quality and security improvements in SonarQube 2025.4. - [SonarQube 2025.5 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-5/): To explore newly released features and performance enhancements in SonarQube 2025.5. - [SonarQube 2025.6 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-6/): To examine updates and refinements included in SonarQube 2025.6. - [SonarQube 10.0 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-0/): To learn about major updates and innovations introduced in SonarQube 10.0. - [SonarQube 10.1 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-1/): To review enhancements and fixes delivered in SonarQube 10.1. - [SonarQube 10.2 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-2/): To explore improvements and feature updates in SonarQube 10.2. - [SonarQube 10.3 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-3/): To discover new capabilities and optimizations in SonarQube 10.3. - [SonarQube 10.4 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-4/): To examine the latest code quality and security enhancements in SonarQube 10.4. - [SonarQube 10.5 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-5/): To learn about feature additions and improvements in SonarQube 10.5. - [SonarQube 10.6 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-6/): To review updates and refinements introduced in SonarQube 10.6. - [SonarQube 10.7 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-7/): To explore enhancements and fixes delivered in SonarQube 10.7. - [SonarQube Server 10.8 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-server-10-8/): To discover the latest updates specific to SonarQube Server 10.8. - [SonarQube Server 2025.1 LTA – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-server-2025-1-lta-whats-new/): To learn about the features and improvements included in the SonarQube Server 2025.1 Long-Term Active release. - [SonarQube 9.8 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-9-8/): To review updates and enhancements delivered in SonarQube 9.8. --- ## Solutions - [Advanced SAST Solution](https://www.sonarsource.com/solutions/security/sast/): Promotes the Advanced SAST solution for enhancing code security and identifying vulnerabilities in software applications. - [SonarQube Security Solutions](https://www.sonarsource.com/solutions/security/): Promoting SonarQube's integrated security solutions for ensuring code quality and vulnerability detection in software development. - [Code Coverage Solutions](https://www.sonarsource.com/solutions/code-coverage/): Evaluate code quality through detailed code coverage metrics and improve overall software reliability and maintainability. - [Advanced Security Solutions](https://www.sonarsource.com/solutions/security/advanced-security-request/): Promote advanced security solutions for software development to ensure secure code and compliance. - [Sonar's Open Source Commitment](https://www.sonarsource.com/solutions/commitment-to-open-source/): Promoting Sonar's dedication to open-source solutions and engaging with the developer community for continuous improvement. - [Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/): To promote SonarQube as a comprehensive tool for improving code quality and security through effective code reviews. - [AI Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/ai): To promote SonarQube as a comprehensive tool for improving ai code quality and code security through effective ai code reviews. - [Automated Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/automated): To promote SonarQube as a comprehensive automated tool for improving code quality and security through effective automated code reviews. - [AI CodeFix Solutions](https://www.sonarsource.com/solutions/ai/ai-codefix/): Promotes AI CodeFix solutions for accelerated code issue resolution with one-click AI recommendations. - [Developers tools](https://www.sonarsource.com/solutions/for-developers/): Empower developers to write better, quality code through continuous feedback and quality assurance tools. - [Software Composition Analysis](https://www.sonarsource.com/solutions/security/sca/): Promote software composition analysis for identifying vulnerabilities and ensuring compliance in third-party dependencies. - [Software Development Use Cases](https://www.sonarsource.com/solutions/use-cases/): To showcase software development use cases and solutions for improving code quality and managing technical debt. - [Enterprise Software Solutions](https://www.sonarsource.com/solutions/for-enterprise/): Promote Sonar's solutions for secure and efficient enterprise software development. - [Manage Technical Debt](https://www.sonarsource.com/solutions/reduce-technical-debt/): Promote strategies and solutions to manage technical debt and enhance software development quality and efficiency. - [AI Code Assurance Solutions](https://www.sonarsource.com/solutions/ai/ai-code-assurance/): Promote AI Code Assurance solutions for high-quality and secure AI-generated code validation. - [AI Code Quality Solutions](https://www.sonarsource.com/solutions/ai/): Promote AI solutions for quality assurance in code development. - [Advanced Secrets Detection](https://www.sonarsource.com/solutions/secrets-detection/): To promote Sonar's advanced secrets detection solutions that protect source code from security vulnerabilities. - [DevOps Transformation Solutions](https://www.sonarsource.com/solutions/devops-transformation/): Promote tools for enhancing code quality and efficiency in DevOps transformation using Sonar products. - [Infrastructure as Code Security](https://www.sonarsource.com/solutions/infrastructure-as-code/): Promotes a solution for analyzing code quality and security in Infrastructure as Code environments. - [Reduce Outsourcing Risks](https://www.sonarsource.com/solutions/reduce-outsourcing-software-development-risk/): Help organizations minimize risks associated with outsourcing software development by enforcing standardized coding practices. - [Secure By Design Code](https://www.sonarsource.com/solutions/secure-by-design-code/): Promoting secure software development practices to reduce risks and integrate security into the coding lifecycle. - [Validate AI code for security and quality](https://www.sonarsource.com/solutions/ai-code-quality/): Tools and methodologies to ensure that AI-generated code meets security and quality standards. - [Developer security](https://www.sonarsource.com/solutions/developer-security/): Strategies and tools to secure applications and prevent vulnerabilities throughout the development lifecycle. - [Automated code review](https://www.sonarsource.com/solutions/automated-code-review/): A process that ensures code is secure and of high quality through automated checks and balances. - [Compliance reporting](https://www.sonarsource.com/solutions/compliance-and-reporting/): Automates the proof of code compliance to meet regulatory and organizational standards. - [SDLC governance](https://www.sonarsource.com/solutions/code-governance/): Aligns AI and developer standards to ensure compliance and quality throughout the Software Development Life Cycle (SDLC). - [Mobile Developers](https://www.sonarsource.com/solutions/mobile-developers/): Help mobile developers find and fix bugs, vulnerabilities, and code quality issues for Android and iOS projects with instant IDE feedback and audit-ready compliance reports. - [Platform Engineering](https://www.sonarsource.com/solutions/platform-engineering): Enable platform engineering teams to standardize tools, automate quality checks, and boost developer productivity, integrating AI-driven remediation for secure code delivery. - [SonarQube, SonarCloud, and SonarLint CI/CD Integrations](https://www.sonarsource.com/solutions/integrations/): This page explains how Sonar products integrate with major DevOps platforms and CI/CD tools to enhance code quality and security through features like pull request decoration and Quality Gates. - [OWASP Security Vulnerability Coverage of Top 10, ASVS & CWE 25 with SonarQube, SonarCloud & SonarLint](https://www.sonarsource.com/solutions/security/owasp/): This page details how Sonar's products help address security vulnerabilities based on OWASP Top 10, ASVS, and CWE Top 25 standards, with features like dedicated security reports and early SAST feedback. - [Code Quality Standards](https://www.sonarsource.com/solutions/quality/): Quality Gates give you a clear go/no-go releasability indicator at every analysis and coalesce the team around a shared vision of quality. - [Taint Analysis](https://www.sonarsource.com/solutions/taint-analysis/): SonarQube's taint analysis is a deep security scan that tracks user-controllable data through your entire application, to identify sophisticated injection vulnerabilities. - [Code Architecture](https://www.sonarsource.com/solutions/architecture/): Software architecture is an essential cornerstone of coding, and yet, it is often overlooked. SonarQube’s architecture capabilities help bring software architecture back under your control. - [Software Development for SMBs](https://www.sonarsource.com/solutions/software-development-for-smbs/): Small and medium business development teams face unique pressure to deliver fast and innovate while managing tight budgets, limited resources, and the complexity of modern stacks. --- ## Integrations ### Root - [SonarSource Integrations](https://www.sonarsource.com/integrations/): To explore integrations that connect SonarSource solutions with popular development tools, CI/CD systems, and collaboration platforms to enhance code quality and security workflows. - [Integrations Overview](https://www.sonarsource.com/integrations/overview/): To get an overview of all available integrations and how they extend SonarSource products into your development ecosystem. ### SCM/CI/DevOps - [GitHub Integration](https://www.sonarsource.com/integrations/github/): To connect SonarSource code quality and security analysis with GitHub for streamlined checks and feedback in your development workflow. - [GitLab Integration](https://www.sonarsource.com/integrations/gitlab/): To integrate SonarSource analysis with GitLab CI/CD for automated quality and security checks in merge requests and pipelines. - [Bitbucket Integration](https://www.sonarsource.com/integrations/bitbucket/): To enable SonarSource code quality and security analysis within Bitbucket Cloud and Server development environments. - [Azure Integration](https://www.sonarsource.com/integrations/azure/): To explore tooling and services that connect SonarSource solutions with Microsoft Azure development and DevOps platforms. - [Azure DevOps Integration](https://www.sonarsource.com/integrations/azure/devops/): To integrate SonarSource code quality and security checks into Azure DevOps pipelines. - [Apache Maven Integration](https://www.sonarsource.com/integrations/apache/maven/): To use SonarSource static analysis with Apache Maven builds for automated quality and security insights. - [Gradle Integration](https://www.sonarsource.com/integrations/gradle/): To integrate SonarSource analysis into Gradle build processes for consistent code quality and security reporting. - [NPM Integration](https://www.sonarsource.com/integrations/npm/): To connect SonarSource static analysis with NPM workflows for monitoring JavaScript and TypeScript code quality and security. - [Docker Scout Integration](https://www.sonarsource.com/integrations/docker/scout/): To integrate Docker Scout with SonarSource analysis for enhanced container security and code quality insights. - [Jenkins Integration](https://www.sonarsource.com/integrations/jenkins/): To incorporate SonarSource code quality and security checks into Jenkins CI/CD pipelines. - [Travis CI Integration](https://www.sonarsource.com/integrations/travis-ci/): To enable SonarSource quality and security analysis in Travis CI workflows. - [CircleCI Integration](https://www.sonarsource.com/integrations/circleci/): To connect SonarSource code quality and security tools with CircleCI for continuous inspection in your builds. - [Codemagic Integration](https://www.sonarsource.com/integrations/codemagic/): To integrate SonarSource quality and security analysis into Codemagic CI/CD for mobile and cross-platform development. - [Harness Integration](https://www.sonarsource.com/integrations/harness/): To integrate SonarSource code quality and security tools with Harness CI/CD workflows. - [Amazon CodeCatalyst Integration](https://www.sonarsource.com/integrations/amazon/codecatalyst/): To use SonarSource static analysis within Amazon CodeCatalyst development environments for improved code quality and security. - [Python PyPI Integration](https://www.sonarsource.com/integrations/python/pypi/): To connect SonarSource code quality and security analysis with Python’s PyPI ecosystem for package and dependency monitoring. ### IDE Integrations - [Eclipse Integration](https://www.sonarsource.com/integrations/eclipse/): To integrate SonarSource code quality and security tools into the Eclipse IDE for continuous inspection during development. - [IntelliJ IDEA Integration](https://www.sonarsource.com/integrations/jetbrains/intellij/): To connect SonarSource static analysis with IntelliJ IDEA for real-time code quality and security feedback. - [PyCharm Integration](https://www.sonarsource.com/integrations/jetbrains/pycharm/): To use SonarSource analysis inside PyCharm for enhanced Python code quality and security insights. - [CLion Integration](https://www.sonarsource.com/integrations/jetbrains/clion/): To bring SonarSource code quality and security checks to C/C++ development inside CLion. - [Visual Studio Integration](https://www.sonarsource.com/integrations/microsoft/visual-studio/): To integrate SonarSource code quality and security analysis with Microsoft Visual Studio IDE workflows. - [Visual Studio Code Integration](https://www.sonarsource.com/integrations/microsoft/vs-code/): To connect SonarSource static analysis tools with Visual Studio Code for inline quality and security insights. - [Android Studio Integration](https://www.sonarsource.com/integrations/android/studio/): To embed SonarSource code quality and security analysis into Android Studio for mobile development. - [Cursor Integration](https://www.sonarsource.com/integrations/cursor/): To integrate SonarSource code quality and security capabilities with Cursor for enhanced coding assistance. - [Zed Integration](https://www.sonarsource.com/integrations/zed/): To connect SonarSource static analysis with the Zed editor to provide quality and security feedback during development. ### AI/LLM Integrations - [Claude Integration](https://www.sonarsource.com/integrations/claude/): To integrate SonarSource code quality and security insights with Claude for enhanced analysis and developer assistance. - [Google Gemini CLI Integration](https://www.sonarsource.com/integrations/google/gemini-cli/): To connect SonarSource’s static analysis capabilities with the Google Gemini CLI for streamlined code quality and security checks from the command line. - [Devin Windsurf Integration](https://www.sonarsource.com/integrations/devin-windsurf/): To explore the Devin Windsurf integration with SonarSource tools for extended code quality and security workflows. ### Platform/Observability/Workflow - [Slack Integration](https://www.sonarsource.com/integrations/slack/): To connect SonarSource code quality and security alerts with Slack for team notifications and collaboration. - [Atlassian Jira Integration](https://www.sonarsource.com/integrations/atlassian/jira/): To integrate SonarSource static analysis with Jira for linking issues and tracking code quality and security work. - [Atlassian Compass Integration](https://www.sonarsource.com/integrations/atlassian/compass/): To connect SonarSource insights with Compass for enhanced developer experience and code quality observability. - [Port Integration](https://www.sonarsource.com/integrations/port/): To integrate SonarSource capabilities with Port for streamlined developer workflows and code quality visibility. - [JFrog Integration](https://www.sonarsource.com/integrations/jfrog/): To connect SonarSource analysis with JFrog tools for artifact management and improved code quality and security tracking. - [Jellyfish Integration](https://www.sonarsource.com/integrations/jellyfish/): To integrate SonarSource quality and security data with Jellyfish for engineering productivity insights. - [Datadog Integration](https://www.sonarsource.com/integrations/datadog/): To send SonarSource metrics and alerts to Datadog for monitoring code quality and security performance. - [MuleSoft Integration](https://www.sonarsource.com/integrations/mulesoft/): To integrate SonarSource code quality and security insights with MuleSoft for API and integration lifecycle visibility. - [SAP Integration](https://www.sonarsource.com/integrations/sap/): To connect SonarSource static analysis with SAP development environments to enhance code quality and security across enterprise landscapes. --- ## Languages - [Multi-language Analysis Tools](https://www.sonarsource.com/knowledge/languages/): To provide resources and tools for effective static code analysis across multiple programming languages. ### Individual Languages - [Java Language Resources](https://www.sonarsource.com/knowledge/languages/java/): To explore best practices, static analysis guidance, and code quality and security insights for Java development. - [JavaScript Language Resources](https://www.sonarsource.com/knowledge/languages/js/): To access code quality and security resources for JavaScript development, including modern frontend and backend frameworks. - [Python Language Resources](https://www.sonarsource.com/knowledge/languages/python/): To learn about static code analysis and secure coding practices for Python applications. - [C# Language Resources](https://www.sonarsource.com/knowledge/languages/csharp/): To improve code quality and security in C# and .NET projects with tailored analysis guidance. - [Go Language Resources](https://www.sonarsource.com/knowledge/languages/go/): To explore code quality and security recommendations for Go (Golang) development. - [Kubernetes Configuration Resources](https://www.sonarsource.com/knowledge/languages/kubernetes/): To strengthen security and reliability in Kubernetes manifests and configuration files. - [Flex Language Resources](https://www.sonarsource.com/knowledge/languages/flex/): To access static analysis and code quality insights for Flex applications. - [Swift Language Resources](https://www.sonarsource.com/knowledge/languages/swift/): To enhance code quality and security in Swift applications for Apple platforms. - [C++ Language Resources](https://www.sonarsource.com/knowledge/languages/cpp/): To apply advanced static analysis and secure coding practices in C++ development. - [PHP Language Resources](https://www.sonarsource.com/knowledge/languages/php/): To improve PHP code quality and security with actionable static analysis guidance. - [COBOL Language Resources](https://www.sonarsource.com/knowledge/languages/cobol/): To modernize and secure legacy COBOL systems with improved code quality practices. - [T-SQL Language Resources](https://www.sonarsource.com/knowledge/languages/t-sql/): To strengthen database code quality and security in T-SQL scripts and stored procedures. - [Terraform Resources](https://www.sonarsource.com/knowledge/languages/terraform/): To enhance infrastructure-as-code security and maintainability in Terraform configurations. - [VB6 Language Resources](https://www.sonarsource.com/knowledge/languages/vb6/): To support quality improvements and maintainability in legacy Visual Basic 6 applications. - [ABAP Language Resources](https://www.sonarsource.com/knowledge/languages/abap/): To improve code quality and security within SAP ABAP development environments. - [PL/I Language Resources](https://www.sonarsource.com/knowledge/languages/pli/): To access static analysis guidance for maintaining and modernizing PL/I applications. - [RPG Language Resources](https://www.sonarsource.com/knowledge/languages/rpg/): To strengthen code quality and reliability in IBM RPG systems. - [Ruby Language Resources](https://www.sonarsource.com/knowledge/languages/ruby/): To apply code quality and security best practices in Ruby applications and frameworks. - [CSS Resources](https://www.sonarsource.com/knowledge/languages/css/): To improve maintainability and quality in CSS stylesheets. - [VB.NET Language Resources](https://www.sonarsource.com/knowledge/languages/vb-net/): To enhance code quality and security in VB.NET applications. - [Objective-C Language Resources](https://www.sonarsource.com/knowledge/languages/objective-c/): To strengthen code quality and security in Objective-C development. - [Scala Language Resources](https://www.sonarsource.com/knowledge/languages/scala/): To improve Scala code quality and reliability with static analysis best practices. - [XML Resources](https://www.sonarsource.com/knowledge/languages/xml/): To ensure well-formed, secure, and maintainable XML configurations and data files. - [Kotlin Language Resources](https://www.sonarsource.com/knowledge/languages/kotlin/): To enhance Kotlin application quality and security with targeted static analysis. - [Docker Resources](https://www.sonarsource.com/knowledge/languages/docker/): To improve container configuration quality and security in Dockerfiles. - [PL/SQL Language Resources](https://www.sonarsource.com/knowledge/languages/pl-sql/): To strengthen database code quality and security in PL/SQL development. - [Dart Language Resources](https://www.sonarsource.com/knowledge/languages/dart/): To improve code quality and security in Dart applications, including Flutter projects. - [AWS CloudFormation Resources](https://www.sonarsource.com/knowledge/languages/cloudformation/): To enhance security and maintainability in AWS CloudFormation infrastructure templates. - [C Language Resources](https://www.sonarsource.com/knowledge/languages/c/): To apply static analysis and secure coding practices to C development projects. - [Rust Language Resources](https://www.sonarsource.com/knowledge/languages/rust/): To improve reliability, safety, and code quality in Rust applications. - [TypeScript Language Resources](https://www.sonarsource.com/knowledge/languages/ts/): To strengthen code quality and security in TypeScript-based applications. - [HTML Resources](https://www.sonarsource.com/knowledge/languages/html/): To ensure maintainable and standards-compliant HTML code. - [Apex Language Resources](https://www.sonarsource.com/knowledge/languages/apex/): To improve code quality and security in Salesforce Apex development. - [Azure Resource Manager Resources](https://www.sonarsource.com/knowledge/languages/azure-resource-manager/): To enhance infrastructure-as-code quality and security in Azure Resource Manager templates. - [MISRA C++ 2023 Resources](https://www.sonarsource.com/knowledge/languages/cpp/misra-cpp-2023/): To apply MISRA C++ 2023 guidelines for safer, standards-compliant C++ development. --- ## Resources ### Root - [SonarSource Resources](https://www.sonarsource.com/resources/): To explore educational content, insights, and materials focused on improving code quality and security across the software development lifecycle. ### Library - [Resource Library](https://www.sonarsource.com/resources/library/): To browse the full library of guides, articles, reports, and thought leadership on code quality and security. - [Guides](https://www.sonarsource.com/resources/library/guide/): To access in-depth guides covering best practices for code quality, secure coding, and modern development workflows. - [Articles](https://www.sonarsource.com/resources/library/article/): To read expert articles and perspectives on code quality, security, and software engineering trends. ### Library Articles - [Refactoring Guide](https://www.sonarsource.com/resources/library/refactoring/): To learn best practices for code refactoring to improve maintainability, reduce technical debt, and enhance overall software quality. - [Preventing the Trojan Horse in Your Dependencies](https://www.sonarsource.com/resources/library/preventing-the-trojan-horse-in-your-dependencies/): To understand how to protect your software supply chain from malicious dependencies and hidden security risks. - [What Is GitLab?](https://www.sonarsource.com/resources/library/what-is-gitlab/): To explore GitLab’s role in DevOps workflows and how it supports code quality and security practices. - [AI Coding Assistants](https://www.sonarsource.com/resources/library/ai-coding-assistants/): To examine the benefits and risks of AI-powered coding assistants in modern software development. - [Enable Azure OpenAI Instance for AI CodeFix](https://www.sonarsource.com/resources/library/enable-azure-openai-instance-for-ai-codefix/): To configure Azure OpenAI for AI CodeFix to enhance automated code quality and security remediation. - [Shift Left](https://www.sonarsource.com/resources/library/shift-left/): To understand the shift-left approach and how early code analysis improves software quality and application security. - [.NET Developer Guide: Automating Quality](https://www.sonarsource.com/resources/library/net-developer-guide-automating-quality/): To automate code quality and security checks in .NET development workflows. - [AI Code Generation](https://www.sonarsource.com/resources/library/ai-code-generation/): To explore how AI code generation impacts developer productivity, quality, and security. - [Integrated Development Environment (IDE)](https://www.sonarsource.com/resources/library/ide/): To understand the role of IDEs in improving developer efficiency and enforcing code quality standards. - [Code Coverage](https://www.sonarsource.com/resources/library/code-coverage/): To learn how measuring code coverage helps ensure test effectiveness and software quality. - [OWASP Guide](https://www.sonarsource.com/resources/library/owasp/): To understand OWASP standards and how they help improve application security and reduce common vulnerabilities. - [Static Code Analysis Using SonarQube](https://www.sonarsource.com/resources/library/static-code-analysis-using-sonarqube/): To learn how static code analysis with SonarQube improves code quality and security across the SDLC. - [Common Vulnerabilities and Exposures (CVE)](https://www.sonarsource.com/resources/library/common-vulnerabilities-exposures/): To understand how CVEs identify, track, and mitigate publicly disclosed security vulnerabilities. - [Source Code Review](https://www.sonarsource.com/resources/library/source-code-review/): To explore best practices for source code review to improve maintainability, security, and software quality. - [Source Code Management](https://www.sonarsource.com/resources/library/source-code-management/): To learn how effective source code management supports collaboration, traceability, and DevOps efficiency. - [Code Quality 2026](https://www.sonarsource.com/resources/library/code-quality-2026/): To explore emerging trends shaping the future of code quality and secure software development. - [Automated Code Scanning](https://www.sonarsource.com/resources/library/automated-code-scanning/): To understand how automated scanning detects vulnerabilities, bugs, and code smells early in development. - [AI-Assisted Software Development](https://www.sonarsource.com/resources/library/ai-assisted-software-development/): To examine how AI tools enhance development workflows while maintaining code quality and security standards. - [Debugging Guide](https://www.sonarsource.com/resources/library/debugging/): To improve debugging practices and reduce defects in complex software systems. - [Monorepo Guide](https://www.sonarsource.com/resources/library/monorepo/): To understand the benefits and challenges of managing code quality in monorepo architectures. - [Synchronizing SonarQube for IDE with Your Project – Part 2](https://www.sonarsource.com/resources/library/synchronizing-sonarqube-for-ide-with-your-project-part-2/): To learn how to properly synchronize SonarQube for IDE with your project for consistent code quality and security feedback. - [Technical Debt](https://www.sonarsource.com/resources/library/technical-debt/): To understand how technical debt accumulates and how to measure, manage, and reduce it effectively. - [DevOps Guide](https://www.sonarsource.com/resources/library/devops/): To explore DevOps principles and how continuous code quality and security integrate into modern pipelines. - [Infrastructure as Code (IaC)](https://www.sonarsource.com/resources/library/infrastructure-as-code/): To strengthen security and maintainability in infrastructure-as-code practices. - [Detect Secrets in the IDE with SonarQube for IDE](https://www.sonarsource.com/resources/library/detect-secrets-in-the-ide-with-sonarlint/): To prevent hard-coded secrets and sensitive data exposure directly within the IDE. - [Platform Engineering Guide](https://www.sonarsource.com/resources/library/platform-engineering-guide/): To understand how platform engineering improves developer experience and governance at scale. - [CI/CD Guide](https://www.sonarsource.com/resources/library/ci-cd/): To learn how continuous integration and continuous delivery pipelines enforce code quality and security gates. - [Application Security Posture Management (ASPM)](https://www.sonarsource.com/resources/library/application-security-posture-management/): To explore strategies for continuously monitoring and improving application security posture. - [Audit Logging](https://www.sonarsource.com/resources/library/audit-logging/): To understand the role of audit logging in compliance, traceability, and security monitoring. - [OpenSSF Scorecard](https://www.sonarsource.com/resources/library/openssf-scorecard/): To evaluate open-source project security using OpenSSF Scorecard best practices. - [Open Source Package](https://www.sonarsource.com/resources/library/open-source-package/): To understand the risks and governance considerations of using open source packages in modern software development. - [Open Source License](https://www.sonarsource.com/resources/library/open-source-license/): To learn about open source licensing models and how they impact compliance and software distribution. - [Code Review](https://www.sonarsource.com/resources/library/code-review/): To explore best practices for effective code review to improve software quality, maintainability, and security. - [Software Quality Assurance (SQA)](https://www.sonarsource.com/resources/library/software-quality-assurance/): To understand how structured quality assurance processes strengthen overall software quality and reliability. - [Static Application Security Testing (SAST)](https://www.sonarsource.com/resources/library/sast/): To learn how SAST tools detect vulnerabilities and security weaknesses early in the development lifecycle. - [Software Composition Analysis (SCA)](https://www.sonarsource.com/resources/library/software-composition-analysis/): To discover how SCA identifies risks in third-party and open source dependencies. - [A Java Developer’s Guide to SonarQube for IDE – Part 1](https://www.sonarsource.com/resources/library/a-java-developer-s-guide-to-sonarqube-for-ide-part-1/): To get started using SonarQube for IDE to improve Java code quality and security during development. - [SonarQube for IDE Plug-in for Cursor](https://www.sonarsource.com/resources/library/sq-ide-plug-in-for-cursor/): To integrate SonarQube for IDE into Cursor for real-time code quality and security insights. - [Audit Trailing](https://www.sonarsource.com/resources/library/audit-trailing/): To understand audit trailing practices for improving traceability and regulatory compliance. - [Data Resiliency](https://www.sonarsource.com/resources/library/data-resiliency/): To explore strategies for ensuring data durability, recovery, and system reliability. - [Code Smells](https://www.sonarsource.com/resources/library/code-smells/): To understand common code smells and how eliminating them improves maintainability and reduces technical debt. - [.NET Developer Guide: Interpreting Results and Mastering Quality Gates](https://www.sonarsource.com/resources/library/net-developer-guide-interpreting-results-and-mastering-quality-gates/): To learn how to interpret analysis results and enforce quality gates in .NET projects. - [What Is GitHub?](https://www.sonarsource.com/resources/library/what-is-github/): To understand GitHub’s role in source code management and collaborative software development. - [7 Habits of Highly Effective AI Coding](https://www.sonarsource.com/resources/library/7-habits-of-highly-effective-ai-coding/): To adopt best practices for using AI coding assistants while maintaining code quality and security. - [What Is Pair Programming?](https://www.sonarsource.com/resources/library/what-is-pair-programming/): To explore the benefits of pair programming for improving collaboration and software quality. - [SonarQube for IDE Extensions for Visual Studio](https://www.sonarsource.com/resources/library/sonarqube-ide-extensions-visual-studio/): To integrate SonarQube for IDE into Visual Studio for real-time quality and security feedback. - [Software Development Lifecycle (SDLC)](https://www.sonarsource.com/resources/library/sdlc/): To understand the phases of the SDLC and how code quality and security practices fit into each stage. - [Integrating the SonarQube MCP Server with Google Antigravity IDE](https://www.sonarsource.com/resources/library/integrating-the-sonarqube-mcp-server-with-google-antigravity-ide/): To configure and integrate SonarQube MCP Server for enhanced IDE-based analysis. - [SLSA (Supply-chain Levels for Software Artifacts)](https://www.sonarsource.com/resources/library/slsa/): To learn about SLSA standards and strengthening software supply chain security. - [Software Supply Chain Security](https://www.sonarsource.com/resources/library/software-supply-chain-security/): To understand risks in the software supply chain and how to mitigate them. - [Guide to Avoiding Common Software Performance Issues](https://www.sonarsource.com/resources/library/guide-to-avoiding-common-software-performance-issues/): To identify and prevent common performance bottlenecks that impact software reliability and user experience. - [Software Composition Analysis (SCA) Tools](https://www.sonarsource.com/resources/library/software-composition-analysis-sca-tools/): To evaluate SCA tools that detect vulnerabilities and license risks in third-party dependencies. - [What Is PL/SQL?](https://www.sonarsource.com/resources/library/what-is-pl-sql/): To understand PL/SQL fundamentals and how to maintain secure, high-quality database code. - [Critical Code Issues](https://www.sonarsource.com/resources/library/critical-code-issues/): To learn how to identify and prioritize critical issues that threaten code quality and security. - [Open Source Maintainers](https://www.sonarsource.com/resources/library/open-source-maintainers/): To explore the role of open source maintainers in sustaining secure and reliable software ecosystems. - [Exploits](https://www.sonarsource.com/resources/library/exploits/): To understand how exploits work and how proactive code analysis reduces vulnerability exposure. - [Setup SonarQube for IDE Plug-in for IntelliJ](https://www.sonarsource.com/resources/library/setup-sq-ide-plugin-for-intellij/): To configure SonarQube for IDE in IntelliJ for real-time code quality and security feedback. - [Analyze Java Code Using SonarQube Cloud](https://www.sonarsource.com/resources/library/analyze-java-code-using-sonarcloud/): To learn how to analyze Java projects using SonarQube Cloud for automated code quality and security checks. - [Secure Coding](https://www.sonarsource.com/resources/library/secure-coding/): To adopt secure coding practices that prevent vulnerabilities and strengthen application security. - [The Strategic Shift to AI-Native IDEs](https://www.sonarsource.com/resources/library/the-strategic-shift-to-ai-native-ides/): To explore how AI-native IDEs are transforming developer workflows while maintaining quality and security standards. - [How to Integrate SonarQube with Windsurf IDE](https://www.sonarsource.com/resources/library/how-to-integrate-sonarqube-with-windsurf-ide/): To configure SonarQube integration with Windsurf IDE for continuous code quality and security feedback. - [OWASP and LLM Code Generation](https://www.sonarsource.com/resources/library/owasp-llm-code-generation/): To understand OWASP guidance related to large language model (LLM) code generation risks and security considerations. - [LLM Deployment Choice](https://www.sonarsource.com/resources/library/llm-deployment-choice/): To evaluate deployment models for large language models and their implications for security and compliance. - [Autoscaling](https://www.sonarsource.com/resources/library/autoscaling/): To explore autoscaling strategies that improve system performance, resilience, and cost efficiency. - [DevSecOps](https://www.sonarsource.com/resources/library/devsecops/): To integrate security practices directly into DevOps pipelines for continuous application security. - [Error Handling Guide](https://www.sonarsource.com/resources/library/error-handling-guide/): To implement robust error handling practices that improve reliability and maintainability. - [Static Code Analysis](https://www.sonarsource.com/resources/library/static-code-analysis/): To understand how static code analysis detects bugs, vulnerabilities, and code smells early in development. - [Integrating SonarQube MCP Server with Cursor](https://www.sonarsource.com/resources/library/integrating-sonarqube-mcp-server-with-cursor/): To connect the SonarQube MCP Server with Cursor for enhanced IDE-based analysis. - [Code Review in Continuous Integration](https://www.sonarsource.com/resources/library/code-review-continuous-integration/): To combine code review practices with CI workflows to enforce quality gates automatically. - [Threat Intelligence](https://www.sonarsource.com/resources/library/threat-intelligence/): To leverage threat intelligence to proactively manage software vulnerabilities and security risks. - [SonarQube for IDE Extension for VS Code](https://www.sonarsource.com/resources/library/sq-ide-extension-for-vscode/): To integrate SonarQube for IDE into Visual Studio Code for real-time code quality and security feedback. - [Cybersecurity Regulatory Compliance](https://www.sonarsource.com/resources/library/cybersecurity-regulatory-compliance/): To understand how regulatory requirements impact application security and development practices. - [What Is Bitbucket?](https://www.sonarsource.com/resources/library/what-is-bitbucket/): To explore Bitbucket’s role in source code management and CI/CD workflows. - [Cyclomatic Complexity](https://www.sonarsource.com/resources/library/cyclomatic-complexity/): To understand how cyclomatic complexity measures code maintainability and risk. - [What Is SCA Scanning?](https://www.sonarsource.com/resources/library/what-is-sca-scanning/): To learn how software composition analysis scanning detects vulnerable dependencies. - [Linter](https://www.sonarsource.com/resources/library/linter/): To understand how linters enforce coding standards and improve software quality. - [Integrate SonarQube for IDE and GitHub Copilot in VS Code](https://www.sonarsource.com/resources/library/integrate-sonarqube-for-ide-and-github-copilot-in-visual-studio-code/): To combine AI coding assistance with real-time code quality and security checks in VS Code. - [Source Code](https://www.sonarsource.com/resources/library/source-code/): To understand the importance of well-structured, maintainable source code in software development. - [Remote Code Execution (RCE)](https://www.sonarsource.com/resources/library/remote-code-execution/): To learn how remote code execution vulnerabilities occur and how to prevent them. - [Application Security](https://www.sonarsource.com/resources/library/application-security/): To explore practices and tools that strengthen application security throughout the SDLC. - [What Is Azure DevOps?](https://www.sonarsource.com/resources/library/what-is-azure-devops/): To understand Azure DevOps services and how they support CI/CD and collaborative development workflows. - [Open Source](https://www.sonarsource.com/resources/library/open-source/): To explore the benefits, risks, and governance considerations of using open source software. - [AI Agents in the SDLC](https://www.sonarsource.com/resources/library/ai-agents-in-sdlc/): To examine how AI agents are influencing the software development lifecycle while maintaining code quality and security. - [SonarQube on AWS EKS (Kubernetes)](https://www.sonarsource.com/resources/library/sonarqube-aws-eks-kubernetes/): To deploy SonarQube on AWS EKS for scalable, cloud-native code quality and security analysis. - [Why Use a Linter?](https://www.sonarsource.com/resources/library/why-linter/): To understand how linters improve coding standards, maintainability, and defect prevention. - [C Programming Language](https://www.sonarsource.com/resources/library/c-programming-language/): To explore best practices for writing secure and maintainable C code. - [Developer Compliance](https://www.sonarsource.com/resources/library/developer-compliance/): To align development practices with regulatory and organizational compliance requirements. - [Introduction to AI CodeFix](https://www.sonarsource.com/resources/library/introduction-to-ai-codefix/): To learn how AI CodeFix helps remediate code quality and security issues efficiently. - [Enabling Anthropic Claude 3.7 Sonnet for AI CodeFix](https://www.sonarsource.com/resources/library/enabling-anthropic-claude-3-7-sonnet-for-ai-codefix/): To configure Claude 3.7 Sonnet to support AI CodeFix capabilities. - [Vulnerability Management](https://www.sonarsource.com/resources/library/vulnerability-management/): To implement effective vulnerability management processes for secure software delivery. - [What Is C#?](https://www.sonarsource.com/resources/library/what-is-c-sharp/): To understand the fundamentals of C# and how to maintain high code quality and security in .NET development. - [Code Scanning](https://www.sonarsource.com/resources/library/code-scanning/): To explore how automated code scanning detects bugs, vulnerabilities, and maintainability issues early. - [How-to Guide for AI Code Assurance](https://www.sonarsource.com/resources/library/how-to-guide-for-ai-code-assurance/): To implement AI-driven code assurance practices that strengthen quality and security. - [Code Base in Software Development](https://www.sonarsource.com/resources/library/code-base-in-software-development/): To understand how managing a codebase effectively improves maintainability and reduces technical debt. - [Complying with AI Policies in Code Development](https://www.sonarsource.com/resources/library/complying-with-ai-policies-in-code-development/): To align AI-assisted development practices with governance and compliance requirements. - [What Is Jira?](https://www.sonarsource.com/resources/library/what-is-jira/): To explore Jira’s role in issue tracking and DevOps collaboration. - [Improve Your DevOps Pipeline](https://www.sonarsource.com/resources/library/improve-your-devops-pipeline/): To optimize DevOps pipelines with integrated code quality and security controls. - [What Is Bug Detection?](https://www.sonarsource.com/resources/library/what-is-bug-detection/): To understand how automated and manual techniques identify software defects. - [Software Bill of Materials (SBOM)](https://www.sonarsource.com/resources/library/software-bill-of-materials/): To learn how SBOMs improve software supply chain transparency and security. - [.NET Developer Guide: Analyzation](https://www.sonarsource.com/resources/library/net-developer-guide-analyzation/): To analyze .NET projects effectively using automated code quality and security tools. - [Getting Started with SonarQube Cloud](https://www.sonarsource.com/resources/library/getting-started-with-sonarqube-cloud/): To begin using SonarQube Cloud for automated code quality and security analysis in your CI/CD workflows. - [Quality Gate](https://www.sonarsource.com/resources/library/quality-gate/): To understand how quality gates enforce code quality and security standards before code is merged or deployed. - [Software Bugs](https://www.sonarsource.com/resources/library/software-bugs/): To explore the causes of software bugs and how proactive code analysis helps prevent them. - [Strategies for Managing Code Quality in Outsourced Software Development](https://www.sonarsource.com/resources/library/strategies-for-managing-code-quality-in-outsourced-software-development/): To maintain code quality, security, and governance when working with distributed or outsourced teams. - [DevOps Transformation with Static Code Analysis](https://www.sonarsource.com/resources/library/devops-transformation-static-code-analysis/): To drive DevOps transformation by embedding static code analysis into continuous delivery pipelines. - [AI Code Generation: Benefits and Risks](https://www.sonarsource.com/resources/library/ai-code-generation-benefits-risks/): To evaluate the productivity gains and security risks of AI-generated code. - [Generative AI Coding Velocity](https://www.sonarsource.com/resources/library/generative-ai-coding-velocity/): To balance increased AI-driven development speed with sustainable code quality and security. - [NIST SSDF](https://www.sonarsource.com/resources/library/nist-ssdf/): To align development practices with the NIST Secure Software Development Framework. - [Security Technical Implementation Guide (STIG)](https://www.sonarsource.com/resources/library/security-technical-implementation-guide/): To understand STIG requirements and strengthen compliance in secure software development. - [Vibe Coding](https://www.sonarsource.com/resources/library/vibe-coding/): To explore emerging AI-driven coding workflows while maintaining engineering rigor and quality standards. - [Swift Programming Language](https://www.sonarsource.com/resources/library/swift-programming-language/): To explore Swift fundamentals and best practices for writing secure, maintainable applications. - [Developer Security Guide](https://www.sonarsource.com/resources/library/developer-security-guide/): To implement secure coding practices that reduce vulnerabilities and strengthen application security. - [LLM Code Generation](https://www.sonarsource.com/resources/library/llm-code-generation/): To understand how large language models generate code and how to manage associated quality and security risks. - [Secure by Design Starts with Code Quality](https://www.sonarsource.com/resources/library/secure-by-design-starts-with-code-quality/): To embed secure-by-design principles directly into development through strong code quality standards. - [Integrating SonarQube Cloud with Azure](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-azure/): To connect SonarQube Cloud with Azure DevOps for automated quality and security analysis. - [Software Compliance](https://www.sonarsource.com/resources/library/software-compliance/): To align development workflows with regulatory, licensing, and internal compliance requirements. - [Measuring and Identifying Code-Level Technical Debt: A Practical Guide](https://www.sonarsource.com/resources/library/measuring-and-identifying-code-level-technical-debt-a-practical-guide/): To quantify, track, and reduce technical debt at the code level. - [Amazon Q and Code Quality](https://www.sonarsource.com/resources/library/amazon-q-code-quality/): To integrate Amazon Q workflows while maintaining strong code quality and security controls. - [AutoConfig for C and C++](https://www.sonarsource.com/resources/library/autoconfig-for-c-and-cpp/): To simplify static analysis configuration for C and C++ projects. - [Integrating Quality Gates into CI/CD Pipelines](https://www.sonarsource.com/resources/library/integrating-quality-gates-ci-cd-pipeline/): To enforce automated quality gates within CI/CD pipelines for consistent governance. - [SonarQube README Badges](https://www.sonarsource.com/resources/library/sonarqube-readme-badges/): To display code quality and security status directly in your repository README files. - [Code Secrets](https://www.sonarsource.com/resources/library/code-secrets/): To detect and prevent hard-coded secrets that expose applications to security risks. - [Application Programming Interface (API)](https://www.sonarsource.com/resources/library/application-programming-interface/): To understand APIs and how to secure them within modern software architectures. - [Code Standardization and Risk Mitigation in Software Development](https://www.sonarsource.com/resources/library/code-standardization-and-risk-mitigation-in-software-development/): To reduce risk and improve maintainability through consistent coding standards. - [GitHub Copilot and AI-Generated Code](https://www.sonarsource.com/resources/library/github-copilot-ai-generated-code/): To manage the risks and quality implications of AI-generated code from GitHub Copilot. - [Open Source Intelligence](https://www.sonarsource.com/resources/library/open-source-intelligence/): To leverage open source intelligence to identify risks and vulnerabilities in dependencies. - [Model Context Protocol (MCP)](https://www.sonarsource.com/resources/library/model-context-protocol/): To understand how MCP supports AI tool integrations in development environments. - [Outsourced Software Development and Scope Creep](https://www.sonarsource.com/resources/library/outsourced-software-development-and-scope-creep-three-ways-to-manage-teams-at-the-code-level/): To manage scope, quality, and technical debt when working with outsourced teams. - [Kubernetes Guide](https://www.sonarsource.com/resources/library/kubernetes/): To strengthen Kubernetes configurations and improve infrastructure security and reliability. - [Integrating SonarQube Cloud with GitHub](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-github/): To connect SonarQube Cloud with GitHub for automated pull request analysis and quality gates. - [Secrets Management](https://www.sonarsource.com/resources/library/secrets-management/): To implement effective secrets management practices that prevent credential leaks and security breaches. - [Integrating SonarQube Cloud with GitLab](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-gitlab/): To connect SonarQube Cloud with GitLab CI/CD for automated code quality and security checks. - [Shift-Left Security: Advancing Early-Stage Security Integration](https://www.sonarsource.com/resources/library/shift-left-security-advancing-early-stage-security-integration/): To embed security earlier in the development lifecycle to reduce risk and remediation costs. - [FIPS](https://www.sonarsource.com/resources/library/fips/): To understand Federal Information Processing Standards (FIPS) and their relevance to secure software development. - [DevOps Implementation Guide](https://www.sonarsource.com/resources/library/devops-implementation-guide/): To implement DevOps practices that integrate continuous code quality and security controls. - [Distributed Software Development: A Guide to Achieving Code Quality](https://www.sonarsource.com/resources/library/distributed-software-development-a-guide-to-achieving-code-quality/): To maintain consistent code quality across distributed and remote teams. - [SARIF](https://www.sonarsource.com/resources/library/sarif/): To understand the Static Analysis Results Interchange Format (SARIF) and how it standardizes security reporting. - [Google Gemini Code Assist and Code Quality](https://www.sonarsource.com/resources/library/google-gemini-code-assist-quality/): To evaluate Google Gemini Code Assist while maintaining strong code quality and security standards. ### Reports, Whitepapers, Research PDFs - [White Papers](https://www.sonarsource.com/resources/white-papers/): To access in-depth white papers on code quality and security, DevOps, and secure software development best practices. - [451 Research Report](https://www.sonarsource.com/resources/451-research-report/): To review independent research insights on application security and static analysis market trends. - [IDC Report](https://www.sonarsource.com/resources/idc-report/): To explore IDC analysis on code quality, application security, and development productivity. - [Developer Survey Report](https://www.sonarsource.com/resources/developer-survey-report/): To understand developer perspectives on code quality, security, and AI-assisted development. - [Developer SDLC Compliance Checklist](https://www.sonarsource.com/resources/developer-sdlc-compliance-checklist/): To use a practical checklist for aligning development workflows with SDLC compliance requirements. - [Developer SDLC Compliance Guide](https://www.sonarsource.com/resources/developer-sdlc-compliance-guide/): To implement structured compliance practices within the software development lifecycle. - [Safeguarding AI-Generated Code](https://www.sonarsource.com/resources/safeguarding-ai-code/): To mitigate risks associated with AI-generated code while maintaining high code quality and security standards. - [GigaOm AST Radar Report](https://www.sonarsource.com/resources/gigaom-ast-radar/): To evaluate application security testing (AST) solutions through GigaOm’s industry analysis. - [G2 Grid Report 2025](https://www.sonarsource.com/resources/g2-grid-report-2025/): To review customer-driven rankings and performance insights from G2’s market grid. - [7 Habits of Highly Effective AI Coding](https://www.sonarsource.com/resources/7-habits-of-highly-effective-ai-coding/): To adopt best practices for using AI coding assistants responsibly and effectively. - [7 Habits of Highly Effective AI Coding – eBook](https://www.sonarsource.com/resources/7-habits-of-highly-effective-ai-coding-ebook/): To download the comprehensive eBook on improving AI-assisted coding while maintaining quality and security. - [The Coding Personalities of Leading LLMs](https://www.sonarsource.com/resources/the-coding-personalities-of-leading-llms/): To compare how leading large language models approach code generation and quality. - [The State of Code Security Report](https://www.sonarsource.com/resources/the-state-of-code-security-report/): To explore trends, risks, and insights shaping modern code security practices. - [The State of Code Reliability Report](https://www.sonarsource.com/resources/the-state-of-code-reliability-report/): To understand key findings on improving software reliability and defect prevention. - [The State of Code Maintainability Report](https://www.sonarsource.com/resources/the-state-of-code-maintainability-report/): To analyze trends in maintainability, technical debt, and long-term code health. - [NIST SSDF Code Security Requirements](https://www.sonarsource.com/resources/nist-ssdf-code-security-requirements/): To align development practices with NIST Secure Software Development Framework requirements. - [Developer Guide to AI-Assisted Software Development](https://www.sonarsource.com/resources/developer-guide-to-ai-assisted-software-development/): To implement AI-assisted development practices while maintaining strong governance and security. - [Cognitive Complexity](https://www.sonarsource.com/resources/cognitive-complexity/): To understand cognitive complexity and how it measures code readability and maintainability. --- ## Blog ### Root - [SonarSource Blog](https://www.sonarsource.com/blog/): To share insights and updates on coding practices, security, and AI in software development. ### Blog Tags - [AI Blog Tag](https://www.sonarsource.com/blog/tag/ai/): To explore blog articles focused on AI in software development, including AI code generation, AI CodeFix, and AI-assisted quality practices. - [Code Security Blog Tag](https://www.sonarsource.com/blog/tag/code-security/): To read insights and updates on improving code security and preventing software vulnerabilities. - [Code Quality Blog Tag](https://www.sonarsource.com/blog/tag/code-quality/): To discover best practices, trends, and thought leadership on maintaining high code quality. - [Company News Blog Tag](https://www.sonarsource.com/blog/tag/company-news/): To stay updated on SonarSource announcements, milestones, and corporate updates. - [SonarQube Server Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-server/): To explore updates, features, and best practices related to SonarQube Server. - [SonarQube Cloud Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-cloud/): To read the latest news, enhancements, and use cases for SonarQube Cloud. - [SonarQube for IDE Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-for-ide/): To learn about real-time code quality and security feedback within IDE workflows. - [Partner Integrations Blog Tag](https://www.sonarsource.com/blog/tag/partner-integrations/): To explore integration announcements and ecosystem partnerships. - [Governance Blog Tag](https://www.sonarsource.com/blog/tag/governance/): To understand strategies for enforcing quality gates, compliance, and development governance. - [Languages Blog Tag](https://www.sonarsource.com/blog/tag/languages/): To explore articles focused on programming language support and analysis improvements. - [Vulnerability Research Blog Tag](https://www.sonarsource.com/blog/tag/vulnerability-research/): To read in-depth vulnerability research and security findings from SonarSource experts. - [SonarQube MCP Server Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-mcp-server/): To explore content related to SonarQube MCP Server integrations and AI-powered workflows. ### Individual Blog Articles - [Sonar Named Leader in G2 Spring Report](https://www.sonarsource.com/blog/sonar-named-leader-in-g2-spring-report/): To learn how Sonar was recognized as a leader in G2’s Spring report for code quality and security solutions. - [Exploring the New Enhancements in SonarQube](https://www.sonarsource.com/blog/exploring-the-new-enhancements-in-sonarqube/): To discover the latest features and improvements in SonarQube for advancing code quality and security. - [Thoughts on Claude and Code Security](https://www.sonarsource.com/blog/thoughts-on-claude-code-security/): To examine security considerations and risks associated with AI-generated code from Claude. - [A Comparison of Claude Opus 4.5 and 4.6](https://www.sonarsource.com/blog/a-comparison-of-claude-opus-4-5-and-4-6/): To compare performance, quality, and security implications of different Claude Opus model versions. - [How SonarQube Enables DORA Compliance for Financial Institutions](https://www.sonarsource.com/blog/how-sonarqube-enables-dora-compliance-for-financial-institutions/): To understand how SonarQube supports regulatory compliance such as DORA through code quality and security governance. - [CRA: Navigating Speed and Security with AI Coding](https://www.sonarsource.com/blog/cra-navigating-speed-and-security-with-ai-coding/): To balance development velocity and compliance under the Cyber Resilience Act using AI-assisted coding responsibly. - [Achieve MISRA C 2023 Compliant Source Code](https://www.sonarsource.com/blog/achieve-misra-c-2023-compliant-source-code/): To implement MISRA C 2023 standards for safer, standards-compliant C development. - [Manage Duplicated Code with Sonar](https://www.sonarsource.com/blog/manage-duplicated-code-with-sonar/): To detect and reduce duplicated code to improve maintainability and reduce technical debt. - [The Power of Deeper SAST](https://www.sonarsource.com/blog/sonar-power-of-deeper-sast/): To explore how advanced static application security testing uncovers deeper security vulnerabilities. - [Announcing SonarQube Server 2026.1 LTA](https://www.sonarsource.com/blog/announcing-sonarqube-server-2026-1-lta/): To review new capabilities and long-term active (LTA) enhancements in SonarQube Server 2026.1. - [Using Dashboards with SonarQube Cloud](https://www.sonarsource.com/blog/using-dashboards-with-sonarqube-cloud/): To leverage dashboards for better visibility into code quality and security metrics. - [Solving the Engineering Productivity Paradox](https://www.sonarsource.com/blog/solving-the-engineering-productivity-paradox/): To address productivity challenges while maintaining high code quality and security standards. - [Stop Malicious Packages in Your CI/CD Pipeline with SonarQube](https://www.sonarsource.com/blog/stop-malicious-packages-in-your-ci-cd-pipeline-with-sonarqube/): To prevent malicious open-source packages from compromising your CI/CD workflows. - [Secrets Detection CLI Beta](https://www.sonarsource.com/blog/secrets-detection-cli-beta/): To explore the beta release of a CLI tool for detecting exposed secrets in codebases. - [SonarQube Code Coverage](https://www.sonarsource.com/blog/sonarqube-code-coverage/): To understand how SonarQube measures and visualizes code coverage to strengthen test effectiveness. - [What Is Taint Analysis?](https://www.sonarsource.com/blog/what-is-taint-analysis/): To learn how taint analysis tracks untrusted data flows to prevent injection and other security vulnerabilities. - [SonarQube Bug Detection Advances](https://www.sonarsource.com/blog/sonarqube-bug-detection-advances/): To explore improvements in automated bug detection capabilities. - [Deeper SAST Uncovers Hidden Security Vulnerabilities](https://www.sonarsource.com/blog/deeper-sast-uncovers-hidden-security-vulnerabilities/): To understand how enhanced SAST techniques reveal hidden security flaws. - [State of Open Source Licenses Today](https://www.sonarsource.com/blog/state-of-open-source-licenses-today/): To analyze current trends and risks related to open-source licensing. - [Why Claude Opus 4.6 Requires Verification](https://www.sonarsource.com/blog/why-claude-opus-4-6-requires-verification/): To understand the importance of validating AI-generated code outputs for quality and security. - [Claude Code + SonarQube MCP: Building an Autonomous Code Review Workflow](https://www.sonarsource.com/blog/claude-code-sonarqube-mcp-building-an-autonomous-code-review-workflow/): To integrate Claude Code with SonarQube MCP for automated, AI-assisted code review. - [How AI Is Redefining Technical Debt](https://www.sonarsource.com/blog/how-ai-is-redefining-technical-debt/): To explore how AI-assisted development impacts the measurement and management of technical debt. - [The AI Coding Trust Gap](https://www.sonarsource.com/blog/ai-coding-trust-gap/): To examine the trust challenges associated with AI-generated code and how to mitigate associated risks. - [Agentic AI and the Automation Shift](https://www.sonarsource.com/blog/agentic-ai-automation-shift/): To explore how agentic AI is transforming software automation and impacting code quality and security practices. - [Shadow AI Is Already Writing Your Code](https://www.sonarsource.com/blog/shadow-ai-is-already-writing-your-code/): To understand the risks of ungoverned AI coding tools and how to maintain visibility and control. - [Introducing Audit Logs in SonarQube Cloud: Enhancing Compliance and Security](https://www.sonarsource.com/blog/introducing-audit-logs-in-sonarqube-cloud-enhancing-compliance-and-security/): To learn how audit logs in SonarQube Cloud strengthen governance, traceability, and compliance. - [Announcing SonarQube Advanced Security](https://www.sonarsource.com/blog/announcing-sonarqube-advanced-security/): To discover enhanced security capabilities for deeper vulnerability detection and risk management. - [Cognitive Complexity: Because Testability and Understandability Matter](https://www.sonarsource.com/blog/cognitive-complexity-because-testability-understandability/): To understand cognitive complexity and how it improves code readability and maintainability. - [What Is Code Quality?](https://www.sonarsource.com/blog/what-is-clean-code/): To explore the principles of writing maintainable, reliable, and secure code aligned with modern code quality standards. - [Bugs and Vulnerabilities as First-Class Citizens in the SonarQube Quality Model](https://www.sonarsource.com/blog/bugs-and-vulnerabilities-are-1st-class-citizens-in-sonarqube-quality-model-along-with-code-smells/): To understand how SonarQube prioritizes bugs, vulnerabilities, and code smells within its quality model. - [SonarQube for IDE: Announcing Support for AI-Native IDEs](https://www.sonarsource.com/blog/sonarqube-ide-announcing-support-for-ai-native-ides/): To explore expanded support for AI-native IDE environments in SonarQube for IDE. - [How Sonar Helps with NIST SSDF](https://www.sonarsource.com/blog/how-sonar-helps-with-nist-ssdf/): To align development practices with the NIST Secure Software Development Framework using Sonar solutions. - [How Sonar Helps Achieve a Strong SOC 2 Type II Report](https://www.sonarsource.com/blog/how-sonar-helps-achieve-a-strong-soc-2-type-ii-report/): To support SOC 2 Type II compliance through code quality and security controls. - [ASP.NET Core Web Apps](https://www.sonarsource.com/blog/asp-net-core-web-apps/): To improve code quality and security in ASP.NET Core web applications. - [Introducing Native Jira Cloud Integration for SonarQube Cloud](https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/): To integrate SonarQube Cloud directly with Jira Cloud for streamlined issue tracking. - [Join the SonarQube Remediation Agent Beta](https://www.sonarsource.com/blog/join-the-sonarqube-remediation-agent-beta/): To participate in the beta program for automated remediation powered by AI. - [Introducing Architecture in SonarQube](https://www.sonarsource.com/blog/introducing-architecture-in-sonarqube/): To explore architectural analysis capabilities for improving maintainability and governance. - [SonarQube and Port Integration](https://www.sonarsource.com/blog/sonarqube-and-port/): To integrate SonarQube insights with Port for enhanced developer experience and visibility. - [A Technical Look at SonarSweep for GPT-OSS-20B](https://www.sonarsource.com/blog/a-technical-look-at-sonarsweep-for-gpt-oss-20b/): To analyze how SonarSweep evaluates and improves AI-generated code quality. - [False Positives: Our Enemies, but Maybe Your Friends](https://www.sonarsource.com/blog/false-positives-our-enemies-but-maybe-your-friends/): To understand false positives in static analysis and how they impact quality and security workflows. - [SonarQube for IDE: Our Journey This Year and a Sneak Peek into 2025](https://www.sonarsource.com/blog/sonarqube-for-ide-our-journey-this-year-and-sneak-peek-into-2025/): To review recent progress and upcoming roadmap highlights for SonarQube for IDE. - [Introducing Scoped Organization Tokens for SonarQube Cloud](https://www.sonarsource.com/blog/introducing-scoped-organization-tokens-for-sonarqube-cloud/): To enhance security and access control with scoped organization tokens in SonarQube Cloud. - [ISO 27001: Why It Matters](https://www.sonarsource.com/blog/iso-27001-importance/): To understand the importance of ISO 27001 certification and how it supports strong security governance and compliance. - [AutoConfig for C++: Code Analysis Redefined](https://www.sonarsource.com/blog/autoconfig-cpp-code-analysis-redefined/): To explore how AutoConfig simplifies and improves static analysis for C++ projects. - [How to Enable Your Development Team to Deliver High-Quality Code](https://www.sonarsource.com/blog/how-to-enable-your-development-team-to-deliver-clean-code/): To empower teams with practices and tools that improve maintainability and code quality. - [Microservices, Major Headaches: Detecting Vulnerabilities in Erxes Microservices](https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices/): To uncover security vulnerabilities in microservices architectures and improve application security. - [Apache Dubbo Consumer Risks](https://www.sonarsource.com/blog/apache-dubbo-consumer-risks/): To analyze security risks affecting Apache Dubbo consumers and how to mitigate them. - [Avocado Nightmare 2](https://www.sonarsource.com/blog/avocado-nightmare-2/): To investigate complex security vulnerabilities and exploitation techniques discovered by Sonar researchers. - [Dangerous Import: SourceForge Patches Critical Code Vulnerability](https://www.sonarsource.com/blog/dangerous-import-sourceforge-patches-critical-code-vulnerability/): To examine how a critical vulnerability was introduced and mitigated in a widely used project. - [The State of Code Security](https://www.sonarsource.com/blog/the-state-of-code-security/): To review trends and findings related to modern code security challenges. - [Ollama Remote Code Execution: Securing the Code That Runs LLMs](https://www.sonarsource.com/blog/ollama-remote-code-execution-securing-the-code-that-runs-llms/): To analyze remote code execution vulnerabilities affecting LLM tooling and how to secure them. - [Caught in the Fortinet (3/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-3-3/): To understand advanced exploitation techniques targeting FortiClient deployments. - [Code Security for Conversational AI: Uncovering a Zip Slip in Eddi](https://www.sonarsource.com/blog/code-security-for-conversational-ai-uncovering-a-zip-slip-in-eddi/): To explore a Zip Slip vulnerability affecting conversational AI platforms. - [Caught in the Fortinet (1/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-1-3/): To examine initial attack vectors targeting FortiClient installations. - [Caught in the Fortinet (2/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-2-3/): To analyze follow-up exploitation techniques impacting enterprise environments. - [Remote Code Execution in Melis Platform](https://www.sonarsource.com/blog/remote-code-execution-in-melis-platform/): To investigate a remote code execution vulnerability and remediation strategies. - [Pretalx Vulnerabilities: How to Get Accepted at Every Conference](https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/): To understand vulnerabilities affecting Pretalx and their broader security implications. - [A Twist in the Code: OpenMeetings Vulnerabilities](https://www.sonarsource.com/blog/a-twist-in-the-code-openmeetings-vulnerabilities-through-unexpected-application-state/): To explore security flaws caused by unexpected application states in OpenMeetings. - [Pimcore: One Click, Two Security Vulnerabilities](https://www.sonarsource.com/blog/pimcore-one-click-two-security-vulnerabilities/): To analyze multiple vulnerabilities discovered in Pimcore installations. - [Cacti Unauthenticated Remote Code Execution](https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/): To review a critical unauthenticated RCE vulnerability in Cacti. - [C# Logging Best Practices](https://www.sonarsource.com/blog/csharp-logging/): To improve logging practices in C# applications for better observability and security. - [OneDev Remote Code Execution](https://www.sonarsource.com/blog/onedev-remote-code-execution/): To analyze a remote code execution vulnerability affecting OneDev and how to mitigate exploitation risks. - [Securing Developer Tools: A New Supply Chain Attack on PHP](https://www.sonarsource.com/blog/securing-developer-tools-a-new-supply-chain-attack-on-php/): To examine a supply chain attack targeting PHP development tooling and its security implications. - [Securing Developer Tools: Argument Injection in VS Code](https://www.sonarsource.com/blog/securing-developer-tools-argument-injection-in-vscode/): To understand how argument injection vulnerabilities can compromise developer environments. - [OpenEMR Remote Code Execution in Your Healthcare System](https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/): To explore a critical RCE vulnerability affecting OpenEMR and healthcare systems. - [The Coding Personalities of Leading LLMs](https://www.sonarsource.com/blog/the-coding-personalities-of-leading-llms/): To compare how leading large language models generate code and assess quality and security implications. - [Patches, Collisions, and Root Shells: A Pwn2Own Adventure](https://www.sonarsource.com/blog/patches-collisions-and-root-shells-a-pwn2own-adventure/): To dive into advanced exploitation techniques demonstrated during Pwn2Own. - [Hexacon 2023 Highlights](https://www.sonarsource.com/blog/hexacon2023-highlights/): To review key security research highlights and vulnerability findings presented at Hexacon 2023. - [The State of Code Reliability](https://www.sonarsource.com/blog/the-state-of-code-reliability/): To explore trends and research findings on improving software reliability. - [The State of Code Maintainability](https://www.sonarsource.com/blog/the-state-of-code-maintainability/): To analyze insights on maintainability, complexity, and technical debt. - [Why Code Security Matters Even in Hardened Environments](https://www.sonarsource.com/blog/why-code-security-matters-even-in-hardened-environments/): To understand why secure coding practices remain critical even in hardened infrastructures. - [Diving into JumpServer: Attacker’s Gateway to Internal Networks (1/2)](https://www.sonarsource.com/blog/diving-into-jumpserver-attackers-gateway-to-internal-networks-1-2/): To investigate vulnerabilities that allow attackers to pivot into internal networks. - [Avocado Nightmare 1](https://www.sonarsource.com/blog/avocado-nightmare-1/): To explore the initial findings in a complex vulnerability research case study. - [Reply-to-Calc: The Attack Chain to Compromise Mailspring](https://www.sonarsource.com/blog/reply-to-calc-the-attack-chain-to-compromise-mailspring/): To dissect a multi-step attack chain leading to compromise via Mailspring. - [Double Dash, Double Trouble: A Subtle SQL Injection Flaw](https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw/): To understand how subtle SQL injection vulnerabilities can bypass common defenses. - [Beware the Cookie Monster: Cyberhaven Extension Vulnerability Allowed Cookie Theft](https://www.sonarsource.com/blog/beware-the-cookie-monster-cyberhaven-extension-vulnerability-allowed-cookie-theft/): To examine how a browser extension vulnerability enabled session cookie theft. - [Data in Danger: Detecting XSS in Grafana (CVE-2025-2703)](https://www.sonarsource.com/blog/data-in-danger-detecting-xss-in-grafana-cve-2025-2703/): To analyze an XSS vulnerability in Grafana and its security impact. - [10 Unknown Security Pitfalls for Python](https://www.sonarsource.com/blog/10-unknown-security-pitfalls-for-python/): To uncover lesser-known Python security pitfalls and how to prevent common vulnerabilities. - [Disclosing Information with a Side Channel in Django](https://www.sonarsource.com/blog/disclosing-information-with-a-side-channel-in-django/): To examine how side-channel vulnerabilities in Django can leak sensitive information. - [Zimbra Mail: Stealing Clear-Text Credentials via Memcache Injection](https://www.sonarsource.com/blog/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/): To analyze a memcache injection vulnerability that exposed credentials in Zimbra Mail. - [Odoo: Get Your Content-Type Right or Else](https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else/): To understand how improper content-type handling can introduce security vulnerabilities in Odoo. - [It’s a SNMP Trap: Gaining Code Execution on LibreNMS](https://www.sonarsource.com/blog/it-s-a-snmp-trap-gaining-code-execution-on-librenms/): To investigate an exploitation path leading to remote code execution in LibreNMS. - [Checkmk RCE Chain (Part 1)](https://www.sonarsource.com/blog/checkmk-rce-chain-1/): To dissect the first stage of a remote code execution attack chain in Checkmk. - [Zabbix: Case Study of Unsafe Session Storage](https://www.sonarsource.com/blog/zabbix-case-study-of-unsafe-session-storage/): To explore how insecure session storage mechanisms can lead to compromise. - [Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (Part 1)](https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/): To analyze unpatched vulnerabilities affecting Gogs and their impact on development environments. - [Securing Kotlin Apps with SonarQube: Real-World Examples](https://www.sonarsource.com/blog/securing-kotlin-apps-with-sonarqube-real-world-examples/): To improve Kotlin application security using practical static analysis examples. - [Java 22: Leveraging Unnamed Variables and Patterns](https://www.sonarsource.com/blog/java-22-leverage-unnamed-variables-and-patterns/): To explore new Java 22 language features and their implications for cleaner, more maintainable code. - [Security Vulnerabilities in CasaOS](https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos/): To examine discovered vulnerabilities in CasaOS and how to mitigate them. - [phpBB3: PHAR Deserialization to Remote Code Execution](https://www.sonarsource.com/blog/phpbb3-phar-deserialization-to-remote-code-execution/): To understand how PHAR deserialization can lead to RCE in phpBB3. - [Spring Framework Pitfalls](https://www.sonarsource.com/blog/spring-framework-pitfalls/): To identify common security and reliability pitfalls in Spring Framework applications. - [PHP Supply Chain Attack on Composer](https://www.sonarsource.com/blog/php-supply-chain-attack-on-composer/): To analyze a supply chain attack targeting Composer in the PHP ecosystem. - [Securing Developer Tools: Git Integrations](https://www.sonarsource.com/blog/securing-developer-tools-git-integrations/): To explore security risks in Git integrations and how to harden development workflows. - [Securing Developer Tools: Package Managers](https://www.sonarsource.com/blog/securing-developer-tools-package-managers/): To examine security risks in package managers and how supply chain attacks can compromise development environments. - [OpenEMR 5.0.2.1 Command Injection Vulnerability](https://www.sonarsource.com/blog/openemr-5-0-2-1-command-injection-vulnerability/): To analyze a command injection vulnerability affecting OpenEMR and its security impact. - [Pandora FMS 7.4.2 Critical Code Vulnerabilities Explained](https://www.sonarsource.com/blog/pandora-fms-742-critical-code-vulnerabilities-explained/): To understand critical vulnerabilities discovered in Pandora FMS and how they were exploited. - [Pitfalls of Desanitization: Leaking Customer Data from osTicket](https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket/): To explore how improper desanitization can lead to sensitive customer data exposure. - [Code Vulnerabilities Leak Emails in Proton Mail](https://www.sonarsource.com/blog/code-vulnerabilities-leak-emails-in-proton-mail/): To investigate vulnerabilities that exposed user email data in Proton Mail. - [Code Vulnerabilities Put Skiff Emails at Risk](https://www.sonarsource.com/blog/code-vulnerabilities-put-skiff-emails-at-risk/): To examine security flaws that threatened confidentiality in Skiff’s email platform. - [Remote Code Execution in Tutanota Desktop Due to Code Flaw](https://www.sonarsource.com/blog/remote-code-execution-in-tutanota-desktop-due-to-code-flaw/): To analyze an RCE vulnerability impacting the Tutanota desktop application. - [NoSQL Injections in Rocket.Chat](https://www.sonarsource.com/blog/nosql-injections-in-rocket-chat/): To understand how NoSQL injection vulnerabilities can compromise real-time communication platforms. - [Why ORMs and Prepared Statements Can’t Always Win](https://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/): To explore limitations of ORMs and prepared statements in preventing injection vulnerabilities. - [Sanitize Client-Side? Why Server-Side HTML Sanitization Is Doomed to Fail](https://www.sonarsource.com/blog/sanitize-client-side-why-server-side-html-sanitization-is-doomed-to-fail/): To examine the pitfalls of improper HTML sanitization strategies. - [Never Underestimate CSRF: Why Origin Reflection Is a Bad Idea](https://www.sonarsource.com/blog/never-underestimate-csrf-why-origin-reflection-is-a-bad-idea/): To analyze CSRF vulnerabilities and the dangers of flawed origin validation. - [Front-End Frameworks: When Bypassing Built-In Sanitization Backfires](https://www.sonarsource.com/blog/front-end-frameworks-when-bypassing-built-in-sanitization-might-backfire/): To understand how bypassing framework protections can introduce XSS and other vulnerabilities. - [Hack the Stack with LocalStack](https://www.sonarsource.com/blog/hack-the-stack-with-localstack/): To explore how misconfigurations in local cloud emulation tools can expose security risks. - [Ghost Admin Takeover](https://www.sonarsource.com/blog/ghost-admin-takeover/): To investigate vulnerabilities that enabled administrative account compromise in Ghost CMS. - [Path Traversal Vulnerabilities in Icinga Web](https://www.sonarsource.com/blog/path-traversal-vulnerabilities-in-icinga-web/): To analyze path traversal flaws that allowed unauthorized file access. - [Checkmk RCE Chain (Part 2)](https://www.sonarsource.com/blog/checkmk-rce-chain-2/): To continue exploring the multi-stage remote code execution chain in Checkmk. - [Checkmk RCE Chain (Part 3)] (https://www.sonarsource.com/blog/checkmk-rce-chain-3/): To examine the final exploitation steps in the Checkmk RCE attack chain. - [Visual Studio Code Security: A Deep Dive into Your Favorite Editor](https://www.sonarsource.com/blog/visual-studio-code-security-deep-dive-into-your-favorite-editor/): To examine security risks and attack surfaces within Visual Studio Code and its extensions. - [New Spring Framework Rules in SonarQube](https://www.sonarsource.com/blog/new-spring-framework-rules-in-sonarqube/): To explore new static analysis rules that strengthen security and reliability in Spring applications. - [No, C Static Analysis Does Not Have to Be Painful](https://www.sonarsource.com/blog/no-c-static-analysis-does-not-have-to-be-painful/): To demonstrate how modern static analysis simplifies improving C code quality and security. - [Sonar at Pwn2Own Toronto 2022](https://www.sonarsource.com/blog/sonar-at-pwn2own-toronto-2022/): To review Sonar’s participation and vulnerability research showcased at Pwn2Own Toronto 2022. - [TyphoonCon 2023 Wrap-Up](https://www.sonarsource.com/blog/typhooncon-2023-wrap-up/): To summarize key security research insights and conference highlights from TyphoonCon 2023. - [Java SAST Benchmarks: Why You Shouldn’t Trust Them Blindly](https://www.sonarsource.com/blog/java-sast-benchmarks-why-you-shouldn-t-trust-them-blindly/): To critically evaluate SAST benchmark methodologies and their limitations. - [Troopers 2023 Conference Takeaways](https://www.sonarsource.com/blog/troopers-2023-conference-takeaways/): To reflect on key security trends and vulnerability research presented at Troopers 2023. - [Black Hat 2023 Overview](https://www.sonarsource.com/blog/blackhat-2023-overview/): To review major themes and research findings from Black Hat 2023. - [Reflections from OffensiveCon 2023](https://www.sonarsource.com/blog/reflections-from-offensivecon-2023/): To explore advanced offensive security insights shared at OffensiveCon 2023. - [Bits from Hexacon 2022](https://www.sonarsource.com/blog/bits-from-hexacon-2022/): To recap notable vulnerability research and security discussions from Hexacon 2022. - [Diving into JumpServer: Attacker’s Gateway to Internal Networks (2/2)](https://www.sonarsource.com/blog/diving-into-jumpserver-attackers-gateway-to-internal-networks-2-2/): To continue analyzing exploitation techniques that enable internal network compromise. - [The Tainted Voyage: Uncovering Voyager’s Vulnerabilities](https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/): To investigate vulnerabilities discovered in Voyager and their security implications. - [Magento RCE via XSS](https://www.sonarsource.com/blog/magento-rce-via-xss/): To understand how a cross-site scripting flaw led to remote code execution in Magento. - [Zimbra Webmail Compromise via Email](https://www.sonarsource.com/blog/zimbra-webmail-compromise-via-email/): To analyze how crafted emails enabled compromise of Zimbra webmail systems. - [WordPress CSRF to RCE](https://www.sonarsource.com/blog/wordpress-csrf-to-rce/): To examine how a CSRF vulnerability escalated to remote code execution in WordPress. - [Horde Webmail RCE via Email](https://www.sonarsource.com/blog/horde-webmail-rce-via-email/): To analyze how crafted emails led to remote code execution in Horde Webmail. - [RainLoop: Emails at Risk Due to Code Flaw](https://www.sonarsource.com/blog/rainloop-emails-at-risk-due-to-code-flaw/): To examine vulnerabilities that exposed user emails in RainLoop. - [SonarQube for IDE Supports Go Analysis](https://www.sonarsource.com/blog/sonarlint-supports-go-analysis/): To explore expanded Go language support in SonarQube for IDE for improved code quality and security. - [Exploiting Hibernate Injections](https://www.sonarsource.com/blog/exploiting-hibernate-injections/): To understand how Hibernate-based injection vulnerabilities can lead to serious security breaches. - [Encoding Differentials: Why Charset Matters](https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/): To explore how character encoding mismatches can introduce subtle security flaws. - [Joomla: Multiple XSS Vulnerabilities](https://www.sonarsource.com/blog/joomla-multiple-xss-vulnerabilities/): To investigate cross-site scripting vulnerabilities affecting Joomla installations. - [mXSS: The Vulnerability Hiding in Your Code](https://www.sonarsource.com/blog/mxss-the-vulnerability-hiding-in-your-code/): To understand mutation-based XSS (mXSS) and how it bypasses common sanitization defenses. - [Remote Code Execution in Mailcow: Always Sanitize Error Messages](https://www.sonarsource.com/blog/remote-code-execution-in-mailcow-always-sanitize-error-messages/): To analyze how improper error handling led to RCE in Mailcow. - [Sonar at JSNation 2023 in Amsterdam](https://www.sonarsource.com/blog/sonar-at-jsnation-2023-in-amsterdam/): To recap insights and highlights from JSNation 2023. - [Sonar’s Scoring on the Top 3 Java SAST Benchmarks](https://www.sonarsource.com/blog/sonar-s-scoring-on-the-top-3-java-sast-benchmarks/): To evaluate Sonar’s performance across leading Java SAST benchmark tests. - [Reflections from DevNexus: The Largest Java Conference in the U.S.A.](https://www.sonarsource.com/blog/reflections-from-devnexus-the-largest-java-conference-in-the-u-s-a/): To review key Java ecosystem trends and conference insights from DevNexus. - [WordPress File Delete to Code Execution](https://www.sonarsource.com/blog/wordpress-file-delete-to-code-execution/): To examine how a file deletion flaw escalated to remote code execution in WordPress. - [Smartstore.NET: Malicious Message Leading to E-Commerce Takeover](https://www.sonarsource.com/blog/smartstorenet-malicious-message-leading-to-e-commerce-takeover/): To analyze how a crafted message enabled compromise of an e-commerce platform. - [MyBB Stored XSS to RCE](https://www.sonarsource.com/blog/mybb-stored-xss-to-rce/): To understand how a stored XSS vulnerability escalated to remote code execution in MyBB. - [Enhancing SAST Detection: Leveraging Benchmarks for Measuring Progress](https://www.sonarsource.com/blog/enhancing-sast-detection-leveraging-benchmarks-for-measuring-progress/): To explore how benchmarks can guide improvements in static application security testing. - [Why Mail Is Dangerous in PHP](https://www.sonarsource.com/blog/why-mail-is-dangerous-in-php/): To investigate common security pitfalls in PHP mail handling implementations. - [Grav CMS Code Execution Vulnerabilities](https://www.sonarsource.com/blog/grav-cms-code-execution-vulnerabilities/): To analyze vulnerabilities that enabled code execution in Grav CMS. - [WordPress Core Unauthenticated Blind SSRF](https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/): To examine an unauthenticated server-side request forgery vulnerability in WordPress core. - [WordPress Object Injection Vulnerability](https://www.sonarsource.com/blog/wordpress-object-injection-vulnerability/): To understand how object injection vulnerabilities can compromise WordPress environments. --- ## Customer Stories ### Root - [Customer Stories](https://www.sonarsource.com/customers/): To explore how leading organizations use Sonar solutions to improve code quality and security at scale. ### Individual Customer Stories - [FedEx Customer Story](https://www.sonarsource.com/customers/fedex/): To learn how FedEx strengthens code quality and security across its global software systems. - [Nasdaq Customer Story](https://www.sonarsource.com/customers/nasdaq/): To discover how Nasdaq ensures reliable and secure software in high-stakes financial environments. - [National Australia Bank Customer Story](https://www.sonarsource.com/customers/national-australia-bank/): To see how National Australia Bank advances code quality and regulatory compliance. - [Digital Turbine Customer Story](https://www.sonarsource.com/customers/digital-turbine/): To explore how Digital Turbine improves development efficiency and code quality. - [Allegiant Customer Story](https://www.sonarsource.com/customers/allegiant/): To understand how Allegiant enhances software reliability and security in aviation systems. - [Vattenfall Customer Story](https://www.sonarsource.com/customers/vattenfall/): To learn how Vattenfall strengthens maintainability and governance across energy software platforms. - [CETIM Customer Story](https://www.sonarsource.com/customers/cetim/): To see how CETIM improves engineering software quality and compliance. - [EDF Customer Story](https://www.sonarsource.com/customers/edf/): To discover how EDF ensures secure and maintainable software in the energy sector. - [Renta Customer Story](https://www.sonarsource.com/customers/renta/): To explore how Renta improves development workflows and code quality standards. - [Infotel Customer Story](https://www.sonarsource.com/customers/infotel/): To learn how Infotel embeds code quality and security into enterprise development. - [Betsson Customer Story](https://www.sonarsource.com/customers/betsson/): To understand how Betsson maintains secure and high-quality software in the gaming industry. - [ANS Customer Story](https://www.sonarsource.com/customers/ans/): To see how ANS enhances DevOps practices with continuous code quality monitoring. - [Centene Customer Story](https://www.sonarsource.com/customers/centene/): To explore how Centene strengthens healthcare software reliability and security. - [AUTO1 Customer Story](https://www.sonarsource.com/customers/auto1/): To discover how AUTO1 maintains scalable, high-quality software across digital platforms. - [SGS Customer Story](https://www.sonarsource.com/customers/sgs/): To learn how SGS improves governance and quality assurance in global operations. - [Covéa Customer Story](https://www.sonarsource.com/customers/covea/): To understand how Covéa ensures secure and maintainable insurance software systems. - [BAE Systems Customer Story](https://www.sonarsource.com/customers/bae-systems/): To see how BAE Systems reinforces secure software development in defense environments. - [AVIV Group Customer Story](https://www.sonarsource.com/customers/aviv-group/): To explore how AVIV Group enhances code quality across digital marketplaces. - [Kroger Customer Story](https://www.sonarsource.com/customers/kroger/): To discover how Kroger strengthens application reliability and security in retail systems. - [HubSpot Customer Story](https://www.sonarsource.com/customers/hubspot/): To learn how HubSpot integrates continuous code quality into rapid product development. - [Wolters Kluwer Customer Story](https://www.sonarsource.com/customers/wolters-kluwer/): To explore how Wolters Kluwer maintains compliance-driven software quality. - [Accor Customer Story](https://www.sonarsource.com/customers/accor/): To understand how Accor improves digital platform reliability and maintainability. - [Allianz Customer Story](https://www.sonarsource.com/customers/allianz/): To see how Allianz strengthens secure software development in financial services. - [Zalando Customer Story](https://www.sonarsource.com/customers/zalando/): To discover how Zalando scales code quality across high-growth e-commerce systems. - [IBM Customer Story](https://www.sonarsource.com/customers/ibm/): To learn how IBM leverages Sonar solutions to enhance enterprise software quality and security. - [Crédit Agricole Customer Story](https://www.sonarsource.com/customers/credit-agricole/): To explore how Crédit Agricole ensures regulatory-compliant and secure banking software. - [Dassault Aviation Customer Story](https://www.sonarsource.com/customers/dassault-aviation/): To understand how Dassault Aviation maintains high-reliability and safety-focused software systems. - [Fidelity Customer Story](https://www.sonarsource.com/customers/fidelity/): To see how Fidelity improves secure and maintainable financial software development. - [NEC Customer Story](https://www.sonarsource.com/customers/nec/): To explore how NEC enhances global software quality and operational resilience. - [Safran Customer Story](https://www.sonarsource.com/customers/safran/): To learn how Safran strengthens secure and safety-critical software engineering practices. --- ## Company ### Root - [SonarSource Company Overview](https://www.sonarsource.com/company/): To learn about SonarSource’s mission, values, and commitment to improving code quality and security across the software industry. - [About SonarSource](https://www.sonarsource.com/company/about/): To explore detailed information about SonarSource’s history, leadership, and vision. - [SonarSource Newsroom](https://www.sonarsource.com/company/newsroom/): To access the latest company news, announcements, and media coverage. - [Press Releases](https://www.sonarsource.com/company/press-releases/): To read official press releases about company milestones, partnerships, and product updates. - [Press Kit](https://www.sonarsource.com/company/press-kit/): To download media assets, logos, and resources for press and analyst use. - [Partners](https://www.sonarsource.com/company/partners/): To explore SonarSource’s ecosystem of technology, consulting, and integration partners. - [Careers at SonarSource](https://www.sonarsource.com/company/careers/): To find career opportunities and learn about working at SonarSource. - [Contact SonarSource](https://www.sonarsource.com/company/contact/): To get in touch with the SonarSource team for general inquiries or support. - [Cookie Policy](https://www.sonarsource.com/company/cookie-policy/): To review how SonarSource uses cookies and similar technologies on its websites. - [Privacy Policy](https://www.sonarsource.com/company/privacy/): To understand SonarSource’s privacy practices and how user data is collected, used, and protected. ### Press Releases - [Sonar Raises $412 Million](https://www.sonarsource.com/company/press-releases/sonar-raises-412-million/): To read the press release announcing Sonar’s $412M funding round supporting expansion in code quality and security offerings. - [Sonar to Acquire Tidelift](https://www.sonarsource.com/company/press-releases/sonar-to-acquire-tidelift/): To learn about Sonar’s strategic acquisition of Tidelift to enhance its open source management capabilities. - [Tariq Shaukat Joins Sonar as Co-CEO](https://www.sonarsource.com/company/press-releases/tariq-shaukat-joins-sonar-as-co-ceo/): To read the announcement of Tariq Shaukat joining Sonar’s leadership team as Co-CEO. - [Sonar Acquires AutoCodeRover to Supercharge Developers with AI Agents](https://www.sonarsource.com/company/press-releases/sonar-acquires-autocoderover-to-supercharge-developers-with-ai-agents/): To explore how Sonar’s acquisition of AutoCodeRover accelerates AI-driven development workflows. - [Sonar ISO Certification](https://www.sonarsource.com/company/press-releases/sonar-iso-certification/): To learn about Sonar achieving ISO certification for its quality and security management systems. - [Sonar Leadership Team Announcement](https://www.sonarsource.com/company/press-releases/sonar-leadership-team/): To read about updates to Sonar’s executive leadership team. - [Sonar Appoints Jean Compeau as CFO and Eyal Ben-David as CLO](https://www.sonarsource.com/company/press-releases/sonar-appoints-jean-compeau-as-chief-financial-officer-and-eyal-ben-david-as-chief-legal-officer/): To see the announcement of new executive appointments to strengthen Sonar’s finance and legal leadership. - [Sonar Records Growth in 2022](https://www.sonarsource.com/company/press-releases/sonar-record-growth-2022/): To review Sonar’s press release on its record growth achievements in 2022. ### Events & Webinars - [SonarSource Events](https://www.sonarsource.com/resources/events/): To explore upcoming events, conferences, and community engagements where SonarSource shares insights on code quality, security, and DevOps practices. - [SonarSource World Tour 2025](https://www.sonarsource.com/resources/events/world-tour-2025/): To learn about the SonarSource World Tour 2025 schedule, locations, and session topics focused on advancing code quality and secure software development. - [SonarSource Webinars](https://www.sonarsource.com/resources/webinars/): To access live and on-demand webinars covering static analysis, code quality and security, AI in software development, and best practices. - [Unpacking the State of Code Reliability Webinar](https://www.sonarsource.com/resources/webinars/unpacking-the-state-of-code-reliability/): To watch a webinar that dives into research findings and strategies for improving software reliability across teams and pipelines. ### Demo - [Request a Demo](https://www.sonarsource.com/request-demo/): To schedule a personalized demo of Sonar solutions and see how code quality and security insights can be integrated into your development workflows. - [Product Demos](https://www.sonarsource.com/product-demos/): To explore on-demand product demonstrations that showcase Sonar solutions in action, including static analysis, quality gates, and security features. - [Contact Enterprise Sales for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/contact-enterprise-sales/): To get in touch with enterprise sales for SonarQube Cloud for tailored pricing, deployment guidance, and scaling support. --- ## Legal ### Root - [Legal Overview](https://www.sonarsource.com/legal/): To review SonarSource’s legal frameworks, policies, and documents governing the use of its products and services. - [Website Terms of Use](https://www.sonarsource.com/legal/website-terms-of-use/): To understand the terms and conditions that apply to your use of the SonarSource website. - [UK Modern Slavery Act Statement](https://www.sonarsource.com/legal/uk-modern-slavery-act-statement/): To read SonarSource’s statement on compliance with the UK Modern Slavery Act and its commitment to ethical practices. - [SonarSource Terms and Conditions (PDF)](https://www.sonarsource.com/docs/sonarsource_terms_and_conditions.pdf: To review the full terms and conditions governing the licensing and use of SonarSource products and services. --- ## Static Assets ### Documents - [The Coding Personalities of Leading LLMs (PDF)](https://www.sonarsource.com/the-coding-personalities-of-leading-llms.pdf): To download the detailed PDF comparing how leading large language models perform in code generation and quality evaluation. - [The State of Code Reliability (PDF)](https://www.sonarsource.com/the-state-of-code-reliability.pdf): To access the full report on trends, insights, and strategies for improving software reliability across organizations. - [The State of Code Security (PDF)](https://www.sonarsource.com/the-state-of-code-security.pdf): To download the comprehensive report on modern code security challenges and mitigation strategies. - [The State of Code Maintainability (PDF)](https://www.sonarsource.com/the-state-of-code-maintainability.pdf): To review findings on maintainability trends, technical debt, and long-term code health. - [The State of Code Languages (PDF)](https://www.sonarsource.com/the-state-of-code-languages.pdf): To explore analysis on programming language usage, risks, and best practices in software development. - [7 Habits of Highly Effective AI Coding (eBook PDF)](https://www.sonarsource.com/7-habits-of-highly-effective-ai-coding-ebook.pdf): To download the eBook on best practices for using AI code assistants while maintaining high quality and secure code. - [ANS Customer Story (2025 PDF)](https://www.sonarsource.com/ans-customer-story-2025.pdf): To download the detailed ANS customer success story showcasing improvements in code quality and security. - [BAE Systems Customer Story (2025 PDF)](https://www.sonarsource.com/BAE-Stystems-Customer-Story-2025.pdf): To access the BAE Systems customer story PDF highlighting secure and maintainable software practices. - [Cognitive Complexity (PDF)](https://www.sonarsource.com/docs/CognitiveComplexity.pdf): To read an in-depth PDF explaining cognitive complexity, its measurement, and its impact on readability and maintainability. ### Support - [Support Center](https://www.sonarsource.com/support/): To access help, technical support resources, and assistance for SonarSource products and services. - [Onboarding Resources](https://www.sonarsource.com/onboarding/): To explore onboarding guides and resources that help teams get started with Sonar solutions quickly and effectively. - [Trust Center](https://www.sonarsource.com/trust-center/): To review SonarSource’s commitments and practices around security, privacy, compliance, and reliability. - [Accessibility Statement](https://www.sonarsource.com/accessibility/): To understand SonarSource’s accessibility standards and how it ensures inclusive access to its digital content. - [Brand Identity Resources](https://www.sonarsource.com/brand-identity/): To download brand assets and guidelines for using SonarSource logos and visual elements. - [Solution Briefs](https://www.sonarsource.com/resources/solution-briefs/): To explore concise solution briefs that outline key value propositions, use cases, and benefits of SonarSource offerings. - [Customer Stories (Resources)](https://www.sonarsource.com/resources/customer-stories/): To browse customer success stories highlighting real-world impact of Sonar solutions on code quality and security practices. - [All Resources](https://www.sonarsource.com/resources/all/): To access the full catalog of resources — including webinars, reports, guides, articles, and events — from SonarSource. - [Languages Knowledge Landing Page](https://www.sonarsource.com/lp/knowledge/languages/): To discover knowledge resources and best practices for static code analysis across multiple programming languages. --- # End of llms-full.txt